Skip to content
RequestGuard Vulnerabilities
Pricing

litellm

Library to easily interface with LLM API providers

PyPI latest 1.101.0 MIT

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

1.101.0

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

Critical

41 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

41

Two LiteLLM versions published containing credential harvesting malware

Affected range

ECOSYSTEM: introduced 1.82.7; last affected 1.82.8

LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit

Affected range

ECOSYSTEM: introduced 0; fixed 1.83.14

Fixed versions: 1.83.14

LiteLLM: Password hash exposure and pass-the-hash authentication bypass

Affected range

ECOSYSTEM: introduced 0; fixed 1.83.0

Fixed versions: 1.83.0

Show 16 more advisories
GHSA-3xr8-qfvj-9p9j Arbitrary file deletion in litellm
GHSA-hx8v-g79f-8w5f LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
GHSA-p897-vf7j-f5h8 BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints
GHSA-m2v5-74w2-qhcj BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure
GHSA-c693-x898-5g4h BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
GHSA-w2mh-qq9q-453x BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens
GHSA-6qr3-3g89-m4jj LiteLLM: Admin Key Handler Has Improper Authorization
GHSA-qmf3-4767-5fg3 LiteLLM: M2M JWT Handler Has Improper Authorization
GHSA-mf52-j94g-746m LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration
GHSA-5jmr-gcrj-2c9q LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
GHSA-qqcv-vg9f-5rr3 litellm vulnerable to improper access control in team management
GHSA-h6m6-jj8v-94jj SQL injection in litellm
GHSA-8j42-pcfm-3467 SQL injection in litellm
GHSA-72m8-9m7m-h278 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
GHSA-4g5m-c9r5-49xf LiteLLM: Local file read via request-supplied OIDC file references
MAL-2026-2144 Malicious code in litellm (PyPI)